ComboFix and Root Repeal didn't run, IE doesn't work and there is still malware.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jose.segue, May 30, 2010.

  1. jose.segue

    jose.segue Private E-2

    But it's better than it was. Running AVG, SuperAntiSpyware and MalwareBytes beat it back, but re-running them shows some malware on re-boots.

    AS catches trojanagent/Gen-Nullo. AVG catches problems in IE from Tool NirCmd, NPI-F, Nircmd-cfxxe which it quanantines, but they keep coming back.

    ComboFix did nothing and RootRepeal gives a messge about initializing, but never does anything. SAS and MWB logs are attached. Error messages and the MG logs folder are available, but could only have 4 attachments.

    Oh yes, and msconfig has disappeared.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    These are not malware. They are valid tools used by many programs including ComboFix. If you did not shutdown or uninstall AVG as requested before running ComboFix, then this would explain why you could not run ComboFix.

    You need to attach the logs from SAS, MBAM, and MGtools.
     
  3. jose.segue

    jose.segue Private E-2

    Today's SAS and MWB files are attached.

    ComboFix still won't run. As before, it will not run with AVG 9 disabled per instructions on their site and confirms, "You are unprotected" on my computer. This time I tried uninstalling AVG and uninstall itself failed. AVG log attached.

    Msconfig, which was reported missing yesterday, seems to have returned.

    IE still won't connect and I ran the SAS fix again today and rebooted before and after just to make sure. Mozilla and Saemonkey browsers seem to be working fine.

    Thx, JS
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go here and download and run the AVG Removal Tool.

    Chaslang is still in need of the C:\MGlogs.zip from running MGtools
     
    Last edited by a moderator: Jun 2, 2010
  5. jose.segue

    jose.segue Private E-2

    Thanks for the pointer to the AVG removal program. ComboFix ran with AVG out, but not with AVG disabled (log attached).

    Rebooted and IE appears to be working once again. Tried RootRepeal twice, changing the name to rr.exe the second time. It won't run, but it's odds were only 50-50 anyway. Moved on to MGTools (log attached).

    Did not re-run SAS or MWB so those logs, available in a previous post, have not changed.

    Plugged Major Geeks to my Facebook friends, one of whom responded that all I needed to do was run ComboFix. Told him, "It ain't that easy. Report to the Major immediately for proper indoctrination!"
     

    Attached Files:

  6. jose.segue

    jose.segue Private E-2

    Out of curiosity I reran SAS and MWB. MWB didn't find anything, but SAS did and I have (and had) deleted what SAS found from the recycle bin. (Log Attached)
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you set this:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

    If not, use this:
    Change Proxy Server

    If you don't know what this is, delete it:
    C:\Documents and Settings\Jose Segue\Local Settings\Application Data\wepooypss

    Otherwise, I am not seeing any issues in your logs. Tell me how things are running.
     
  8. jose.segue

    jose.segue Private E-2

    I didn't set
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    though the HKCU does seem familiar from some of the anti-malware programs I've ran. Is this something I should get rid of? And how?

    I'm not familiar with what a proxy server is. I do use OpenDNS. I did go into IE and Firefox as suggested by the link and did not see any proxy settings there. Since running ComboFix my Internet connections seem normal. Seamonkey and Firefox always worked but IE wouldn't connect at all. It's fine since running C-Fix.

    I remain worried about the problems SAS found per my previous post. Should I be?

    Thx, JS
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing to worry about. If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds